From nobody Mon Sep 28 08:01:30 2026 Received: from mx0a-001b2d01.pphosted.com (mx0a-001b2d01.pphosted.com [148.163.156.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3EBA5384CC2; Mon, 24 Aug 2026 21:56:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.156.1 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787608581; cv=none; b=iGMtUvPpvgyFx4KHfvb2VLL2N3kP5YFAN2igLbcNlSMPZa2S5W9ffvwe2RNG4HoBCYBK7QNrfbCOk6pRTgVttrMOIidQVrUKCsPWJBExLh0gEyt9ukp+6oohblzAsjfpTdSIXO2BxV+VYcIbxP7MvO0zOTJv9ZUpPKbWhTmUm6g= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787608581; c=relaxed/simple; bh=/UlVtfTIQxqU57CW4NDAlN32GL20/n/BAIqXvgZOLfU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Fzu3xXtsQ8KTNNeoYjSfloBilIX0yB7KSebzBCqiwZjMbLfgrVhlbTD5btD/JSZbwoRSumGPtr9Kw1Xw7TuGS7Cous7RInCJ5ycBZllilJgm+/lK2xQxllugpg8TZHG6e4PxO+WbGhbHFMUxYQ45pY36Xq1On7kqT2UR5E6SI14= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=qHO8ii0E; arc=none smtp.client-ip=148.163.156.1 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="qHO8ii0E" Received: from pps.filterd (m0360083.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67OJVTCW2836508; Mon, 24 Aug 2026 21:56:11 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=bgcSHbVr7rPYmHcI1 KU+SingjOpIVb4nyHY1r9vXUpY=; b=qHO8ii0EIXUU6GiNG/snykPCt74D0lyOp kSbQAK1oHjnLDzQrqxRhb/CV65MjiSqoKDC0jCELJns0DU/xYJJN+mC9SqGvhsnB DKAUjMl9jfYso4Ng+JaEwKQGMb3SV/V/yBQQYochaSrOMl7t5vhGZnQySxkHSj9q Xp9/7iwPYMJAyRw/vBx89J+9OudYOm3mIVCuA7OSZite1npEywNsb9EYC8HO7YqU 8mHnNV7n+lJjAAjLa9b+mzh91QtWx/g+OoJQ6rx6kpicQmdlCQHtiKYgLwR+ITOD RwshgcVjI40H6MEayvfgZga1Xn/q6oiqZB7E00t2iLab4DLRp4OmA== Received: from ppma22.wdc07v.mail.ibm.com (5c.69.3da9.ip4.static.sl-reverse.com [169.61.105.92]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4g7393vf4y-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 24 Aug 2026 21:56:10 +0000 (GMT) Received: from pps.filterd (ppma22.wdc07v.mail.ibm.com [127.0.0.1]) by ppma22.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67OLfJvB023999; Mon, 24 Aug 2026 21:56:09 GMT Received: from smtprelay07.wdc07v.mail.ibm.com ([172.16.1.74]) by ppma22.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4g7pfw0tu7-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 24 Aug 2026 21:56:09 +0000 (GMT) Received: from smtpav05.wdc07v.mail.ibm.com (smtpav05.wdc07v.mail.ibm.com [10.39.53.232]) by smtprelay07.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67OLu8gZ31785726 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 24 Aug 2026 21:56:08 GMT Received: from smtpav05.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 78F8A58053; Mon, 24 Aug 2026 21:56:08 +0000 (GMT) Received: from smtpav05.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id A30EC58043; Mon, 24 Aug 2026 21:56:06 +0000 (GMT) Received: from li-4c4c4544-004d-4810-8043-b7c04f423534.ibm.com.com (unknown [9.61.96.163]) by smtpav05.wdc07v.mail.ibm.com (Postfix) with ESMTP; Mon, 24 Aug 2026 21:56:06 +0000 (GMT) From: Anthony Krowiak To: linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, kvm@vger.kernel.org Cc: jjherne@linux.ibm.com, borntraeger@de.ibm.com, mjrosato@linux.ibm.com, pasic@linux.ibm.com, alex@shazbot.org, kwankhede@nvidia.com, fiuczy@linux.ibm.com, pbonzini@redhat.com, frankja@linux.ibm.com, imbrenda@linux.ibm.com, agordeev@linux.ibm.com, hca@linux.ibm.com, gor@linux.ibm.com, stable@vger.kernel.org Subject: [PATCH v2 1/4] s390/vfio-ap: Fix leak of pinned NIB and registered NISC in vfio_ap_irq_enable() Date: Mon, 24 Aug 2026 17:56:00 -0400 Message-ID: <20260824215603.819379-2-akrowiak@linux.ibm.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260824215603.819379-1-akrowiak@linux.ibm.com> References: <20260824215603.819379-1-akrowiak@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-GUID: Vyou1FdRmdlTHh5S3QGHeljXi0Dnzae3 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODI0MDE4MiBTYWx0ZWRfX+JtBa/HMPmLT zUzJ+ZylQIy5vVZHe/lj/qVGgyz/zjEWraFqXDwiUn0h3Xw9cTIPsdt+bptDvo+GAI02Srs6KfA NY3Yb4C9sazD1bbPBwgkLyZIHryOsF/Qt72r+JHCXLEMCvdBXmH+/9TCva9B4WdEDRZ3TC6iFrv jJEVD2fFuuDm8YW7eWWwhjdSurmbwMMyoJRViJ/DPuWLChWw2ZaNfGT3o15lZXGJEjBjWzILj+H TFROV4tkvSKCBwrV59823EZSq8rRL/GmgLlx/KpOK4TLsIwTtGPRsIS7BE5OwCPjhaKRLFJguor Q49MN5+dGZmwzmYH1h2IPTrsgbo+QsqHzRZ8wJE6ks3O0sqT8A6yxIO3zmxYrmBIQ/JMus8/Uuf fIAr+1I6CLZqBDgMqnF8sl0nA204rTNrW6VN8vcE2weAvEf/EVE7JEBalBnslPten1yiSobV3Kp coXwdhbUTubdppnRmag== X-Authority-Analysis: v=2.4 cv=Y/nIdBeN c=1 sm=1 tr=0 ts=6a8cbdfa cx=c_pps a=5BHTudwdYE3Te8bg5FgnPg==:117 a=5BHTudwdYE3Te8bg5FgnPg==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=iQ6ETzBq9ecOQQE5vZCe:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=hmEx05nRRPonxVd58HoA:9 X-Proofpoint-Spam-Info: AW1haW4tMjYwODI0MDE4MiBTYWx0ZWRfX1kzlzegLkAsH uO6mpuZ9fG5o0mbcOZkq5+hu6nfpBkenMtYyv3ULHXz+eYr91cbmk/5tE+KKg7uXo2VZf6P75Am yyA2Fif3lDqcVRSyoKZqLWg0ulmo0YM= X-Proofpoint-ORIG-GUID: Vyou1FdRmdlTHh5S3QGHeljXi0Dnzae3 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-24_06,2026-08-24_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 impostorscore=0 priorityscore=1501 adultscore=0 bulkscore=0 suspectscore=0 malwarescore=0 clxscore=1015 lowpriorityscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608240182 Content-Type: text/plain; charset="utf-8" The vfio_ap_irq_enable() function executes the PQAP(AQIC) instruction to enable interrupts for an AP queue. A switch statement is used to examine the status response code returned from the instruction to determine whether it succeeded or failed and react accordingly. For the default case, the vfio_ap_irq_disable function is invoked to disable interrupts for the queue and clean up the AQIC resources (i.e., unpin the NIB and unregister the NISC). There are a number of problems with this: 1. Neither the q->saved_iova nor q->saved_isc has been set, so the AQIC resources - assuming those values have been previously set - will be the NIB and NISC resources from a prior call; the NIB and NISC from the current call are therefore leaked. 2. Interrupts may never have been enabled. Sending a disable instruction to a queue that the hardware just told you is in a bad state (CHECKSTOPPED, DECONFIGURED, Q_NOT_AVAIL) is at best wasted work and at worst generates a further WARN_ONCE from inside vfio_ap_irq_disable's own default. 3. The hardware just rejected the new ap_aqic() enable attempt with an unexpected status. Disabling a previously-working IRQ config - assuming that is even possible - as a reaction to a failed enable attempt does not make sense; it is actively destructive, tearing down something that was working for no valid reason. The fix is to unregister the NISC and an unpin the NIB in the default case of the switch statement. Fixes: ec89b55e3bce7 ("s390: ap: implement PAPQ AQIC interception in kernel= ") Cc: stable@vger.kernel.org Signed-off-by: Anthony Krowiak --- drivers/s390/crypto/vfio_ap_ops.c | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/drivers/s390/crypto/vfio_ap_ops.c b/drivers/s390/crypto/vfio_a= p_ops.c index 940c0ff668be..22a6ceaa7b56 100644 --- a/drivers/s390/crypto/vfio_ap_ops.c +++ b/drivers/s390/crypto/vfio_ap_ops.c @@ -503,9 +503,12 @@ static struct ap_queue_status vfio_ap_irq_enable(struc= t vfio_ap_queue *q, vfio_unpin_pages(&q->matrix_mdev->vdev, nib, 1); break; default: - pr_warn("%s: apqn %04x: response: %02x\n", __func__, q->apqn, - status.response_code); - vfio_ap_irq_disable(q); + /* We could not modify IRQ settings: clear new configuration */ + ret =3D kvm_s390_gisc_unregister(kvm, isc); + if (ret) + VFIO_AP_DBF_WARN("%s: kvm_s390_gisc_unregister: rc=3D%d isc=3D%d, apqn= =3D%#04x\n", + __func__, ret, isc, q->apqn); + vfio_unpin_pages(&q->matrix_mdev->vdev, nib, 1); break; } =20 --=20 2.53.0 From nobody Mon Sep 28 08:01:30 2026 Received: from mx0a-001b2d01.pphosted.com (mx0a-001b2d01.pphosted.com [148.163.156.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 390D33939A9; Mon, 24 Aug 2026 21:56:22 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.156.1 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787608584; cv=none; b=eFCpZtTBTasWawzgW9vdOY46KPey5ztbEQep3Rnd/WJkRVuMBkfZglQSAm1LAfREisoiBKBo8ImwCSkOUPlgSCSBeN1cSZhmOI+WP9J9cmNmmM3V4h7D2K2M8wy+QZXvJRTDj9k1rkpZMH8sC4kCtfMpq0cCLA9T8Lk2CfYQZro= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787608584; c=relaxed/simple; bh=gOK9NurwxRr2Hb3z/zWeKKCciRyrAVr691ulPhDxv3U=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=p+n9Jyr+OPoXZuhsGW9iZM53rvAWff8TtyP9TNRDY7oZF38r17QlPTVZDkbX9ZBN8WStTu/43tCFoBrXpAF0yx8qhJiIxMNcvRn2iXqlZdcKqgskjWODn46aoh4+YpdhaA6R9HkPEWwqZLbJur5DcjTGDCuq/xdH93kmoltNI2k= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=g6oDxXhQ; arc=none smtp.client-ip=148.163.156.1 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="g6oDxXhQ" Received: from pps.filterd (m0360083.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67OJVTCX2836508; Mon, 24 Aug 2026 21:56:13 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=J+fNENahdLbY5iZ4c Ai/zNdEulv/m6s2LNQjd/WezuA=; b=g6oDxXhQ5D3YdCb9eUpdN91BQfut4AykM X8z33EYlSqUVveBcdkU8O/JyouF0NrPEbdrTw5sQx824VZD6NX0f+nsEW+skXPPn UozycGmVm8yytv5b0FU4HP/H8wxwUtlLpMjndKJGso+OyWjWRexU7vi/NDg3BACz R4LpS6GuRu4LqTggoRfwlxiwdpa64gYCvH30wA6lg76L0OtznPlKBI4PWSD4UL1o wxA++cxrNzbfcFJN6c+jyuIDDmD/R76pWBWBMyEgkpfYm6j2ZXu1rfGWdKTkU6Jg 0nYEdkOAqatZR3RRznSbRd4R6sX3gamWBuPUOKw+TTm/uLRFJ6aNQ== Received: from ppma22.wdc07v.mail.ibm.com (5c.69.3da9.ip4.static.sl-reverse.com [169.61.105.92]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4g7393vf5a-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 24 Aug 2026 21:56:13 +0000 (GMT) Received: from pps.filterd (ppma22.wdc07v.mail.ibm.com [127.0.0.1]) by ppma22.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67OLfJxC024000; Mon, 24 Aug 2026 21:56:12 GMT Received: from smtprelay03.dal12v.mail.ibm.com ([172.16.1.5]) by ppma22.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4g7pfw0tuc-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 24 Aug 2026 21:56:12 +0000 (GMT) Received: from smtpav05.wdc07v.mail.ibm.com (smtpav05.wdc07v.mail.ibm.com [10.39.53.232]) by smtprelay03.dal12v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67OLuA5V9568852 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 24 Aug 2026 21:56:10 GMT Received: from smtpav05.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 83CA858061; Mon, 24 Aug 2026 21:56:10 +0000 (GMT) Received: from smtpav05.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id A5BF458043; Mon, 24 Aug 2026 21:56:08 +0000 (GMT) Received: from li-4c4c4544-004d-4810-8043-b7c04f423534.ibm.com.com (unknown [9.61.96.163]) by smtpav05.wdc07v.mail.ibm.com (Postfix) with ESMTP; Mon, 24 Aug 2026 21:56:08 +0000 (GMT) From: Anthony Krowiak To: linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, kvm@vger.kernel.org Cc: jjherne@linux.ibm.com, borntraeger@de.ibm.com, mjrosato@linux.ibm.com, pasic@linux.ibm.com, alex@shazbot.org, kwankhede@nvidia.com, fiuczy@linux.ibm.com, pbonzini@redhat.com, frankja@linux.ibm.com, imbrenda@linux.ibm.com, agordeev@linux.ibm.com, hca@linux.ibm.com, gor@linux.ibm.com, stable@vger.kernel.org Subject: [PATCH v2 2/4] s390/vfio-ap: Fix failure to release IRQ notification eventfd contexts Date: Mon, 24 Aug 2026 17:56:01 -0400 Message-ID: <20260824215603.819379-3-akrowiak@linux.ibm.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260824215603.819379-1-akrowiak@linux.ibm.com> References: <20260824215603.819379-1-akrowiak@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-GUID: sTH1lMAcz7c9qkwCwRQ0Z2gfIV9oDoki X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODI0MDE4MiBTYWx0ZWRfX8V00Uh3KPq2E TFlrJiTgvl/rnqJIYey0XRMBdCx0GnY+ObvMt3QTMhaRz5bB2pO3I7JKzxdtXT+XOgWPmP30InP 4DaLapBACYDi5UV8sYTnjuVmMwPsUwpsybU6wxACvDM2aIpVOr1xGua4jQqaLvRjeUIs0qq2gx/ KyKUrHveJs6hfocu8EK3FYw/d+1bNMEfIvfQ0P9aALHXPl7R5w6dvkKFH0TWLoMtnCVH8J1lAfA hlqq7ggdj516VdU2634L+uK/BCSpZ9nmL+HCMFMVJDDQ9R/NoRmfMlVhRsVaqtBfgx7cUsSIFdU OpY559TNcas2Fze4X2IdF/CAVIsyqukWeDV8kLJs78uH/GJoJMgfHpfszq7j9RCRdmUJf5z9cIY DqU1cl/lIif0R/ZMQ3oaVLJnTgoCYKZgBXHDZVDiI0AlYNBaLXB6EElweOTUOYGTZhf7ihOGeia 1c+pbdslST00GI0AXYQ== X-Authority-Analysis: v=2.4 cv=Y/nIdBeN c=1 sm=1 tr=0 ts=6a8cbdfd cx=c_pps a=5BHTudwdYE3Te8bg5FgnPg==:117 a=5BHTudwdYE3Te8bg5FgnPg==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=iQ6ETzBq9ecOQQE5vZCe:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=fxeDLeT5AZ2qCvnLJ4gA:9 X-Proofpoint-Spam-Info: AW1haW4tMjYwODI0MDE4MiBTYWx0ZWRfX7qd7FqHv7tKL uQmsrE1wDWHSQ0YYgoyMzg3vWXaP25kJFZI+9p2uyZtAt0mmkQhcl91demiTzgBBPvYA1S6WOoQ Hr+CIPGta+8QW98JXHw3dsysl9Vfhss= X-Proofpoint-ORIG-GUID: sTH1lMAcz7c9qkwCwRQ0Z2gfIV9oDoki X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-24_06,2026-08-24_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 impostorscore=0 priorityscore=1501 adultscore=0 bulkscore=0 suspectscore=0 malwarescore=0 clxscore=1015 lowpriorityscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608240182 Content-Type: text/plain; charset="utf-8" When userspace registers IRQ notification eventfds via the VFIO_DEVICE_SET_IRQS ioctl, vfio_ap_set_request_irq() and vfio_ap_set_cfg_change_irq() each call eventfd_ctx_fdget(), which takes a reference on the eventfd_ctx and stores it in matrix_mdev->req_trigger and matrix_mdev->cfg_chg_trigger respectively. These references are dropped only when userspace explicitly replaces or clears them via a subsequent SET_IRQS call. If the device is closed without that explicit teardown - because the guest exits, the VM process crashes, or the device file is simply closed - neither vfio_ap_mdev_close_device() nor the remove path releases these references. The eventfd_ctx backing objects and their associated file references therefore leak for the lifetime of the kernel. Fix this by introducing vfio_ap_mdev_release_eventfds() and calling it from vfio_ap_mdev_close_device() after vfio_ap_mdev_unset_kvm(). The VFIO core guarantees that close_device is called before vfio_unregister_group_dev() returns in the remove path, so fixing close_device is sufficient to cover both teardown paths. Note: ~~~~ The matrix_dev->mdevs lock must be held during the call to vfio_ap_mdev_release_eventfds(). There is a small window between the calls to vfio_ap_mdev_unset_kvm() which gets and releases the update locks and the acquisition of the matrix_dev->mdevs_lock mutex during which it is possible - although highly unlikely during normal operation - whereby a concurrent SET_IRQS call can get in. Taking matrix_dev->mdevs_lock around vfio_ap_mdev_release_eventfds() is sufficient to make this race-free. The SET_IRQS ioctl path writes req_trigger and cfg_chg_trigger only from vfio_ap_mdev_ioctl(), which holds mdevs_lock for its entire duration and always calls eventfd_ctx_put() on the previous value before storing the new one. Any number of concurrent SET_IRQS calls during the window between vfio_ap_mdev_unset_kvm() and the acquisition of mdevs_lock are therefore safe: each ioctl invocation puts the reference it found and installs a new one, leaving exactly one live reference in the field when it releases the lock. When release_eventfds subsequently acquires mdevs_lock it finds that single surviving reference and puts it. Conversely, a SET_IRQS call that loses the race and blocks on mdevs_lock will find the field NULL after release_eventfds finishes, take ownership of the reference it just created, and install it into a field that will never be read again - a transient leak. To close that final case, callers must ensure no new SET_IRQS ioctls can be issued after close_device() is called, which the VFIO core guarantees by releasing the device file before invoking close_device(). Fixes: bf48961f6f48e ("s390/vfio-ap: realize the VFIO_DEVICE_SET_IRQS ioctl= ") Cc: stable@vger.kernel.org Signed-off-by: Anthony Krowiak Reviewed-by: Matthew Rosato --- drivers/s390/crypto/vfio_ap_ops.c | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/drivers/s390/crypto/vfio_ap_ops.c b/drivers/s390/crypto/vfio_a= p_ops.c index 22a6ceaa7b56..3f99b239fa95 100644 --- a/drivers/s390/crypto/vfio_ap_ops.c +++ b/drivers/s390/crypto/vfio_ap_ops.c @@ -2064,12 +2064,28 @@ static int vfio_ap_mdev_open_device(struct vfio_dev= ice *vdev) return vfio_ap_mdev_set_kvm(matrix_mdev, vdev->kvm); } =20 +static void vfio_ap_mdev_release_eventfds(struct ap_matrix_mdev *matrix_md= ev) +{ + if (matrix_mdev->req_trigger) { + eventfd_ctx_put(matrix_mdev->req_trigger); + matrix_mdev->req_trigger =3D NULL; + } + if (matrix_mdev->cfg_chg_trigger) { + eventfd_ctx_put(matrix_mdev->cfg_chg_trigger); + matrix_mdev->cfg_chg_trigger =3D NULL; + } +} + static void vfio_ap_mdev_close_device(struct vfio_device *vdev) { struct ap_matrix_mdev *matrix_mdev =3D container_of(vdev, struct ap_matrix_mdev, vdev); =20 vfio_ap_mdev_unset_kvm(matrix_mdev); + + mutex_lock(&matrix_dev->mdevs_lock); + vfio_ap_mdev_release_eventfds(matrix_mdev); + mutex_unlock(&matrix_dev->mdevs_lock); } =20 static void vfio_ap_mdev_request(struct vfio_device *vdev, unsigned int co= unt) --=20 2.53.0 From nobody Mon Sep 28 08:01:30 2026 Received: from mx0a-001b2d01.pphosted.com (mx0a-001b2d01.pphosted.com [148.163.156.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6B82D393DC7; Mon, 24 Aug 2026 21:56:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.156.1 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787608600; cv=none; b=uTBkA+I5LbVPnnTMWQoRl0eGSmMuoymMtP5rCvH+QrsCikMh3vJ96b2+vUFFODAyGH5Ste1G8Qcw+Lb7AgONal0Zw05U7QIRrQK3C8rdnFRICcVivy5ge/xTycV/nG1o3QtP/bRvkGCw4tE9vvHvlC8hJjjwPVRe0MMnUOFDxl8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787608600; c=relaxed/simple; bh=tFulEEdlyFB5a8pEXmgRywNNstCIO1qZlDoadWGMYNo=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=FjwEibk6/05zC/1FURIfjj8CdvGH15XxuaoyteTDhfCaBTMa8ehTxm8ZwfMu/Nawppz79ccKxGtGuplrNsT1oKDd44cTdKuEzoXj6hYh96S82eHlxWAxbAYgl+JjQ7nXaYm68Q6Ik9h137uIO4xp/HpQIebJXwNR6EVpphKnBcg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=A0o4Ptre; arc=none smtp.client-ip=148.163.156.1 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="A0o4Ptre" Received: from pps.filterd (m0356517.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67OJVSSt2857838; Mon, 24 Aug 2026 21:56:16 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=iaxnCMCWScUbqw4i3 HTGIrEeljHRN9KNGUjxik8eoCE=; b=A0o4PtreK5yktuDwla1ZF4OxkcHHaC/uQ HIvCTl/ljnwNhLDe9F5s+pUM/1bwTpcbjHP2+TzrVumN7aSwkixEGw96Flljaot7 dtjiPVogMasVvTFlY7vVMJUsSKlRlOJue2CNDcvUWaqbMWkGzQvlSTvJWaO+GDWn Hxwnhoq0im8ZAHqGEC3npxXMSGe3K/mMG94xV7AUNUr3mAwxbPfZL/HNtsdA9zUj BQeNE1RLxrwQfZ6AyRzSNlzue2jd3R4AG8Rch6GRSpwyuT2xJVmjUN81eD6fNoCx gHJkERYUCaB4HKVmoDAgffzUQdAGTMW/9fH/2T2RhMuWg4DRWp1Vw== Received: from ppma21.wdc07v.mail.ibm.com (5b.69.3da9.ip4.static.sl-reverse.com [169.61.105.91]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4g73g4mdva-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 24 Aug 2026 21:56:15 +0000 (GMT) Received: from pps.filterd (ppma21.wdc07v.mail.ibm.com [127.0.0.1]) by ppma21.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67OLfGsJ022136; Mon, 24 Aug 2026 21:56:14 GMT Received: from smtprelay05.dal12v.mail.ibm.com ([172.16.1.7]) by ppma21.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4g7q3jrqax-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 24 Aug 2026 21:56:14 +0000 (GMT) Received: from smtpav05.wdc07v.mail.ibm.com (smtpav05.wdc07v.mail.ibm.com [10.39.53.232]) by smtprelay05.dal12v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67OLuC2Z32506370 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 24 Aug 2026 21:56:13 GMT Received: from smtpav05.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 9573558043; Mon, 24 Aug 2026 21:56:12 +0000 (GMT) Received: from smtpav05.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id B303D58065; Mon, 24 Aug 2026 21:56:10 +0000 (GMT) Received: from li-4c4c4544-004d-4810-8043-b7c04f423534.ibm.com.com (unknown [9.61.96.163]) by smtpav05.wdc07v.mail.ibm.com (Postfix) with ESMTP; Mon, 24 Aug 2026 21:56:10 +0000 (GMT) From: Anthony Krowiak To: linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, kvm@vger.kernel.org Cc: jjherne@linux.ibm.com, borntraeger@de.ibm.com, mjrosato@linux.ibm.com, pasic@linux.ibm.com, alex@shazbot.org, kwankhede@nvidia.com, fiuczy@linux.ibm.com, pbonzini@redhat.com, frankja@linux.ibm.com, imbrenda@linux.ibm.com, agordeev@linux.ibm.com, hca@linux.ibm.com, gor@linux.ibm.com, stable@vger.kernel.org Subject: [PATCH v2 3/4] s390/vfio-ap: Fix unbounded loop in apq_reset_check() Date: Mon, 24 Aug 2026 17:56:02 -0400 Message-ID: <20260824215603.819379-4-akrowiak@linux.ibm.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260824215603.819379-1-akrowiak@linux.ibm.com> References: <20260824215603.819379-1-akrowiak@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-ORIG-GUID: fXA-4VpoV58SSSGvFE2dY0jJ4UaR3pYf X-Proofpoint-Spam-Info: AW1haW4tMjYwODI0MDE4MiBTYWx0ZWRfXzHhI1iOcNbi0 U4WAgWmUfmakwLw6yg++E7I2iklB+lcjsGCn9lamsptMw9Dbb4JgefODupCa4TTCheq363j7fXN l52izQdV3rLZ58hJjWCgxiZnjUmwPdY= X-Proofpoint-GUID: fXA-4VpoV58SSSGvFE2dY0jJ4UaR3pYf X-Authority-Analysis: v=2.4 cv=JZyMa0KV c=1 sm=1 tr=0 ts=6a8cbdff cx=c_pps a=GFwsV6G8L6GxiO2Y/PsHdQ==:117 a=GFwsV6G8L6GxiO2Y/PsHdQ==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=U7nrCbtTmkRpXpFmAIza:22 a=VwQbUJbxAAAA:8 a=VnNF1IyMAAAA:8 a=y3d8e9OS9Gm2Uli4ifAA:9 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODI0MDE4MiBTYWx0ZWRfXwVsJPukXNVtx txy8Hee8V11GpxiESY9Sq3/idECO7XSxhmTqzHq1NsIqS0yxWdmIxIBaIsnnZxOBbfdvRnEcJYK 4gXEAV7/Ez9RcKu2TJVcctnaJVf2SAoNOe5nqQVQ6+ttbUYcDlgNKEASD9tCXDTqGYYqoU9m2Tr QRshbyt9VLtoMA+g7fXIk5fjsEDJF4EL5C4FC1gN83d/SMgN3MqANXylV0LC80VySvIbzEC1ej3 fKlOdMwJk5lghXodz5mDqJJid7w0lFahU03/QPhbVvGoi8iIiL6o81Q36BYN8wk2DyPT21F29Eu f6Wl/FXxD7C61lHHP3bfKgWfP64NQKo596Ct8sHd3gGY608CurvF4hV8kqTrsEuqYolDEx/jjNS 7EradTVx/+ASNpwCG7d6CqH+h4/FN9jNhCZ8QRdgGS+bJP3OCsyOTCX53mEK6QY8eMZNIcXTBZW wI6FHhZy+xVUin6yaFA== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-24_06,2026-08-24_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 clxscore=1015 adultscore=0 priorityscore=1501 impostorscore=0 malwarescore=0 bulkscore=0 lowpriorityscore=0 suspectscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608240182 Content-Type: text/plain; charset="utf-8" The apq_reset_check() worker polls ap_tapq() in a while(true) loop waiting for a queue reset to complete. When ap_tapq() returns AP_RESPONSE_BUSY or AP_RESPONSE_RESET_IN_PROGRESS, apq_status_check() returns -EBUSY and the loop continues after sleeping AP_RESET_MAX_WAIT (20ms). There is no upper bound on how many times the loop iterates, so if the hardware continuously returns a busy response the worker runs indefinitely. This is particularly harmful because several callers of vfio_ap_mdev_reset_queues() and vfio_ap_mdev_reset_qlist() call flush_work() on each queue's reset_work while holding one or more of the global matrix_dev locks (guests_lock, mdevs_lock) or the KVM lock. An indefinitely spinning worker permanently blocks all of those locks, hanging mdev removal, KVM guest teardown, and the VFIO_DEVICE_RESET ioctl path. Fix this by introducing AP_RESET_MAX_WAIT (2000ms) and breaking out of the poll loop when elapsed time reaches that threshold. On timeout the final busy status is written back to q->reset_status so that callers inspecting reset_status.response_code after flush_work() see a non-zero value and can return an appropriate error. vfio_ap_free_aqic_resources() is called before returning to release any KVM ISC registration and pinned NIB page, consistent with all other early-exit paths in the function. Fixes: dd174833e44e ("s390/vfio-ap: remove upper limit on wait for queue re= set to complete") Cc: stable@vger.kernel.org Signed-off-by: Anthony Krowiak --- drivers/s390/crypto/vfio_ap_ops.c | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) diff --git a/drivers/s390/crypto/vfio_ap_ops.c b/drivers/s390/crypto/vfio_a= p_ops.c index 3f99b239fa95..7a9b5448e90a 100644 --- a/drivers/s390/crypto/vfio_ap_ops.c +++ b/drivers/s390/crypto/vfio_ap_ops.c @@ -31,6 +31,7 @@ #define AP_QUEUE_IN_USE "in use" =20 #define AP_RESET_INTERVAL 20 /* Reset sleep interval (20ms) */ +#define AP_RESET_MAX_WAIT 2000 /* Maximum wait for reset (2000ms) */ =20 static int vfio_ap_mdev_reset_queues(struct ap_matrix_mdev *matrix_mdev); static int vfio_ap_mdev_reset_qlist(struct list_head *qlist); @@ -1971,6 +1972,27 @@ static void apq_reset_check(struct work_struct *rese= t_work) status.response_code, status.queue_empty, status.irq_enabled); + if (elapsed >=3D AP_RESET_MAX_WAIT) { + /* + * Timed out waiting for reset to complete. + * + * The AQIC resources associated with this queue - the pinned page + * containing the NIB and the registered guest ISC - cannot be freed + * here. The NIB is the active DMA target for AP interrupt delivery + * until the reset completes; freeing the pinned page while the + * hardware may still write to it would result in a use-after-free + * kernel crash. + * + * If the reset eventually completes, interrupts will be terminated + * and the pinned NIB page and ISC registration will be leaked. This + * is preferable to either a use-after-free or waiting indefinitely: + * apq_reset_check() holds the matrix_dev->mdevs_lock mutex, which + * serializes access to all mdev objects system-wide, so blocking + * here would stall all other guests using AP queues. + */ + memcpy(&q->reset_status, &status, sizeof(status)); + return; + } } else { if (q->reset_status.response_code =3D=3D AP_RESPONSE_RESET_IN_PROGRESS = || q->reset_status.response_code =3D=3D AP_RESPONSE_BUSY || --=20 2.53.0 From nobody Mon Sep 28 08:01:30 2026 Received: from mx0b-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 704A8393DE2; Mon, 24 Aug 2026 21:56:22 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.158.5 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787608584; cv=none; b=bNNgPhTzX8VIzYZtf3OSfC2+QAcsggEp577Hr7cBUDwt3a31bj/A1lVXh++4rTuLFyeW9xauQKNOS449H054hJgsRKMV6mJ88u0EFWZXLNN9Bl7eLtCDwF2y/uXy3NBesFzgyWXmRXfszXSJWfsvk1/NQJ24l0/10Gt/z+IRmfw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787608584; c=relaxed/simple; bh=F9W9GlmdN4Ps18czqNl37cNBvPaUjb2DlghZg3hDGwE=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=qYGz6ftQydkpOpO0h8EJr4AvtXEQIYIFhamKQhG0NKiGMqQLmrWq+GorZK+r4KBQEcEylHzootl2aPdfSUjlgF1VOU3LKVMcxVQkA9QEvI/NB92JwvRc2uTzeKdYD4QWpaDkr7W+2YM0BPc0hv01oTCDol5tlmrPlTNHwyePSOs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=Y7/rtje6; arc=none smtp.client-ip=148.163.158.5 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="Y7/rtje6" Received: from pps.filterd (m0360072.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67OJVwJr2904969; Mon, 24 Aug 2026 21:56:17 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=LzB2TqBJAxvotGL+6 eHP/QguJboiB2pp74KOhywSW4k=; b=Y7/rtje6EkeNwfLy6Uk2a9U/rz1a5Vx3J Xl1qoDQhuznAKltQfEmag7ENY1n90UuEXwLYb7q/tfvs+AV12rEpjMYZsYuqjvDW fPunULDx+HlEisOywDFuvLSsP4uSHR0ATMS0B45oGo1IvyrZtbEpP1w4ZcfUvZ8H 6OH2k/rHg/aVZm7aidDGmJYC9UESQSaAVL16no5H8YiIxMWFHS6fTlyM9yMfVDiy ZR/V+wkoWHzICAWlT82EKZZUZndrCptXwTwbx3QhrkbYLwy88m8yFtR0ASObzK2r GqeMF3fPqNX4W2suVUNquCE0B+fPo/hEOdpzJDxJPnOfIzmzHKTKQ== Received: from ppma12.dal12v.mail.ibm.com (dc.9e.1632.ip4.static.sl-reverse.com [50.22.158.220]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4g73dx46nj-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 24 Aug 2026 21:56:16 +0000 (GMT) Received: from pps.filterd (ppma12.dal12v.mail.ibm.com [127.0.0.1]) by ppma12.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67OLuGMh007115; Mon, 24 Aug 2026 21:56:16 GMT Received: from smtprelay07.dal12v.mail.ibm.com ([172.16.1.9]) by ppma12.dal12v.mail.ibm.com (PPS) with ESMTPS id 4g7p3q0whg-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 24 Aug 2026 21:56:16 +0000 (GMT) Received: from smtpav05.wdc07v.mail.ibm.com (smtpav05.wdc07v.mail.ibm.com [10.39.53.232]) by smtprelay07.dal12v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67OLuEt928639756 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 24 Aug 2026 21:56:14 GMT Received: from smtpav05.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 80A0158043; Mon, 24 Aug 2026 21:56:14 +0000 (GMT) Received: from smtpav05.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id C46DE58053; Mon, 24 Aug 2026 21:56:12 +0000 (GMT) Received: from li-4c4c4544-004d-4810-8043-b7c04f423534.ibm.com.com (unknown [9.61.96.163]) by smtpav05.wdc07v.mail.ibm.com (Postfix) with ESMTP; Mon, 24 Aug 2026 21:56:12 +0000 (GMT) From: Anthony Krowiak To: linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org, kvm@vger.kernel.org Cc: jjherne@linux.ibm.com, borntraeger@de.ibm.com, mjrosato@linux.ibm.com, pasic@linux.ibm.com, alex@shazbot.org, kwankhede@nvidia.com, fiuczy@linux.ibm.com, pbonzini@redhat.com, frankja@linux.ibm.com, imbrenda@linux.ibm.com, agordeev@linux.ibm.com, hca@linux.ibm.com, gor@linux.ibm.com Subject: [PATCH v2 4/4] s390/vfio-ap: Use AP_DOMAINS for adm_add bitmap size in vfio_ap_mdev_cfg_add() Date: Mon, 24 Aug 2026 17:56:03 -0400 Message-ID: <20260824215603.819379-5-akrowiak@linux.ibm.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260824215603.819379-1-akrowiak@linux.ibm.com> References: <20260824215603.819379-1-akrowiak@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Info: AW1haW4tMjYwODI0MDE4MiBTYWx0ZWRfX4BRGUW6BTA8b sJtagWgnD8rAQE7mTUAyv/OinfCCFt1LyIPXHILPJl4AsjbZVnXNkayUlFvmOhyNPW2cIhPZljc FePMG2/nuIGxttYrQ/JonY/ldjNzwWM= X-Authority-Analysis: v=2.4 cv=AYuB2XXG c=1 sm=1 tr=0 ts=6a8cbe00 cx=c_pps a=bLidbwmWQ0KltjZqbj+ezA==:117 a=bLidbwmWQ0KltjZqbj+ezA==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=RzCfie-kr_QcCd8fBx8p:22 a=VnNF1IyMAAAA:8 a=gReD5cTbzgwmqpVxveEA:9 X-Proofpoint-ORIG-GUID: QFcQRgpyrDjyJ4K_3bCh03XQKyj2W2FF X-Proofpoint-GUID: QFcQRgpyrDjyJ4K_3bCh03XQKyj2W2FF X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODI0MDE4MiBTYWx0ZWRfX2BVURvVZuJpf aNv5YKTZYQkdOkpAL+NoSINC5ay8v6MIxzjRQZq8ZP4/9f/13DK39XQAPjF32Sy4/9k8LgHNIY2 W69WYI5wLcno1SfkGLVUlI5tnYhEK5qmiZ9FyXE0i2yzPU8i16zg/yvYwM3P1zuJUDROBPlrz+W h4l9O+k0h9NTow0foLeOL144pJVREAbiQ9j2wgzgBo3NsvBOUL/Yn0Slj/RavObCvs1NNJ5NCFI GlfibgPT9usUHS5Rm3EWu1Z1jMQyxuPQ89HcoTomREoppkCf3GFCuDRyzSJu2LiOpJVitL1STd1 /UlP7878TtgGL/3Lrjnw/ZlBx78p0hh0d27OuDHnzpV8+7745xXdcn4bQNWhUjrDL66NiQJ7nL1 mhu7cAmHLVhsIDozCqXFWyfVlS9OQynz0U/VnblQ+FUcBTrqeQyoRMLb1FziwONQ3ecPYshbYXu 4VeL3P03r+iJlNuDQ0w== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-24_06,2026-08-24_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 malwarescore=0 phishscore=0 clxscore=1015 adultscore=0 bulkscore=0 impostorscore=0 priorityscore=1501 lowpriorityscore=0 spamscore=0 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608240182 Content-Type: text/plain; charset="utf-8" Domain and control domain bitmaps are sized by the AP_DOMAINS constant, not AP_DEVICES. The two constants are both 256 today so there is no functional impact, but using the wrong constant is inconsistent with every operation on aqm/adm bitmaps. Use AP_DOMAINS to keep the code consistent and correct in case the two constants ever diverge. Note: This patch was submitted in response to a sashiko review comment pointing out there are other functions besides vfio_ap_mdev_cfg_add(), so there are fixes included here for those also. The subject line was kept the same since this is in v2 of this patch. Signed-off-by: Anthony Krowiak --- drivers/s390/crypto/vfio_ap_ops.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/drivers/s390/crypto/vfio_ap_ops.c b/drivers/s390/crypto/vfio_a= p_ops.c index 7a9b5448e90a..a41d55146db1 100644 --- a/drivers/s390/crypto/vfio_ap_ops.c +++ b/drivers/s390/crypto/vfio_ap_ops.c @@ -1414,7 +1414,7 @@ static void vfio_ap_mdev_hot_unplug_domain(struct ap_= matrix_mdev *matrix_mdev, { DECLARE_BITMAP(apqis, AP_DOMAINS); =20 - bitmap_zero(apqis, AP_DEVICES); + bitmap_zero(apqis, AP_DOMAINS); set_bit_inv(apqi, apqis); vfio_ap_mdev_hot_unplug_domains(matrix_mdev, apqis); } @@ -2738,11 +2738,11 @@ static void vfio_ap_mdev_on_cfg_remove(struct ap_co= nfig_info *cur_config_info, do_remove |=3D bitmap_andnot(aqrem, (unsigned long *)prev_config_info->aqm, (unsigned long *)cur_config_info->aqm, - AP_DEVICES); + AP_DOMAINS); do_remove |=3D bitmap_andnot(cdrem, (unsigned long *)prev_config_info->adm, (unsigned long *)cur_config_info->adm, - AP_DEVICES); + AP_DOMAINS); =20 if (do_remove) vfio_ap_mdev_cfg_remove(aprem, aqrem, cdrem); @@ -2853,7 +2853,7 @@ static void vfio_ap_mdev_cfg_add(unsigned long *apm_a= dd, unsigned long *aqm_add, bitmap_and(matrix_mdev->aqm_add, matrix_mdev->matrix.aqm, aqm_add, AP_DOMAINS); bitmap_and(matrix_mdev->adm_add, - matrix_mdev->matrix.adm, adm_add, AP_DEVICES); + matrix_mdev->matrix.adm, adm_add, AP_DOMAINS); =20 mutex_unlock(&matrix_dev->mdevs_lock); } --=20 2.53.0